aliteq.

wp2shell (CVE-2026-63030): update WordPress now, then check for these signs

No login, no plugin, no odd setup. One anonymous request could take over a default WordPress site. Here is the official advisory in plain English, the fixed versions, and the leftovers that tell you a site was hit.

KernelUpdated 2d ago6 min readWeb story
Lines of HTML code on screen
Share

WordPress shipped security releases 7.0.2, 6.9.5 and 6.8.6 on July 17, 2026 for a bug the finders named wp2shell. It is a pre-login remote code execution flaw in WordPress core. It needs no account, no plugin and no misconfiguration. We ran this site on WordPress for years before the rebuild, so a core bug like this one is not abstract for us.

9.8/ 10

CVSS severity: Critical

Base score in the CVE-2026-63030 record, assigned by WPScan as the CVE numbering authority.

REST API batch route confusion

CVE-2026-63030

the entry point

SQL injection in WP_Query

CVE-2026-60137

the author__not_in parameter

6.9.0–6.9.4, 7.0.0–7.0.1

Full chain affects

fixed in 6.9.5 / 7.0.2

None

Login required

anonymous, default install

What is wp2shell?

wp2shell is a nickname for "WordPress to shell." A shell means the ability to run commands on the server. The name describes going from one anonymous web request to full control of a site. Its official IDs are CVE-2026-63030 and CVE-2026-60137.

Adam Kues of Searchlight Cyber (Assetnote) found it and reported it to WordPress. The finder's disclosure says the attack "has no preconditions" and works on "a stock install of WordPress with no plugins." That is rare. Most WordPress security news is about plugins, which is why this one triggered forced updates.

The official advisory, in plain terms

The official advisory is the WordPress 7.0.2 release post, published July 17, 2026 by John Blackbourn. It calls the release a fix for "one critical and one high severity security issue" and says WordPress.org enabled forced auto-updates for affected sites. The CVE records point back to that post.

Here is what the official sources say, piece by piece:

  • CVE-2026-63030 (GHSA-ff9f-jf42-662q): a REST API batch route confusion. Combined with the SQL injection below, it allows remote code execution. CVSS 9.8, Critical.
  • CVE-2026-60137 (GHSA-fpp7-x2x2-2mjf): WP_Query does not properly clean the author__not_in parameter. On its own it needs a plugin or theme that passes untrusted input to that parameter. CVSS 5.9 from the CVE authority. CISA's own scoring rates it 9.1.
  • Backports: WordPress 6.9 had both bugs and got 6.9.5. WordPress 6.8 had only the SQL injection and got 6.8.6. The 7.1 beta was fixed in beta 2. Versions before 6.8 are not affected.
  • Exploited in the wild: CISA added both CVEs to its Known Exploited Vulnerabilities catalog on July 21, 2026, four days after the patch.
How the wp2shell chain reaches code execution
  1. Anonymous request

    One request to the REST API batch endpoint. No login, no plugin.

  2. Route confusion

    Part of the batch is handled by the wrong route (CVE-2026-63030).

  3. SQL injection

    The misrouted request reaches WP_Query's author__not_in parameter (CVE-2026-60137).

  4. Code execution

    Database access is turned into running the attacker's own code.

  5. Full takeover

    The attacker controls the site and can reach the server under it.

Neither bug is a full takeover alone. Together they are. Sources, WordPress.org advisory and CVE records, read 4 Oct 2026.

For the longer walk-through, see how wp2shell works. We describe the chain, not the steps to run it.

What to verify, not just "did it update"

Check the version number yourself, then look for leftovers. A background update can fail quietly, and a patch does not undo a break-in that already happened.

  1. Log into wp-admin, open Dashboard, then Updates. The version should read 7.0.2, 6.9.5, 6.8.6 or newer. The current release is 7.1.2.
  2. If your host, a plugin or a setting turns off core auto-updates, the forced fix did not reach you. Update by hand now. This is the gap that made managed and self-hosted sites fare so differently.
  3. No login access? The finders host a public checker at wp2shell.com that reports whether an instance is vulnerable.
  4. If the site ran an affected version after July 17, treat it as possibly compromised. Our 10-minute security audit walks through the checks.

What does wp2shell.invalid mean?

If you see an administrator with an email ending in @wp2shell.invalid, public exploit code probably ran on your site. The read-only Compromise Scanner for wp2shell, listed in the WordPress.org plugin directory, checks for exactly this: a "wp2_" login prefix and the "@wp2shell.invalid email used by public exploit code."

The ".invalid" ending is a reserved domain that can never receive mail, so no real user would have it. The same scanner also looks for unexpected admin accounts created since disclosure, gaps in user IDs from accounts created then deleted, and plugin folders named wp2shell_*. Its listing is clear that a match is "not proof of a breach." It is a reason to investigate properly.

Can't update today?

Update as soon as you can. Until then, the finder's disclosure lists temporary measures: block anonymous access to the REST batch API, either with a plugin or by blocking both /wp-json/batch/v1 and ?rest_route=/batch/v1 at a web firewall. The finders warn these can break legitimate features and are stopgaps only.

wp2shell: quick answers

What is the official advisory for CVE-2026-63030?
The WordPress 7.0.2 release post on WordPress.org, dated July 17, 2026, plus GitHub security advisory GHSA-ff9f-jf42-662q. The CVE record links to both. CVE-2026-60137 is covered by GHSA-fpp7-x2x2-2mjf.
What versions of WordPress does wp2shell affect?
The full remote code execution chain affects 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. It is fixed in 6.9.5 and 7.0.2. WordPress 6.8 had only the SQL injection half, which needs a plugin or theme to be reachable, and is fixed in 6.8.6. Versions before 6.8 are not affected.
What is wp2shell?
A nickname meaning "WordPress to shell": going from an anonymous web request to running commands on the server. It refers to CVE-2026-63030 chained with CVE-2026-60137. We explain the full picture in what is wp2shell.
What is wp2shell.invalid?
A fake email domain used by public exploit code when it creates an administrator account. An admin with a @wp2shell.invalid address you did not create is a strong sign your site was attacked. Investigate, do not just delete the user.
Is wp2shell being exploited?
Yes. CISA added both CVE-2026-63030 and CVE-2026-60137 to its Known Exploited Vulnerabilities catalog on July 21, 2026, which means it had evidence of active exploitation.
How do I know if I'm already patched?
Check Dashboard, then Updates in wp-admin. Version 7.0.2, 6.9.5, 6.8.6 or anything newer is patched. Don't assume a background update ran if your host or a plugin disabled core auto-updates.

For the plain-English overview, start with what is wp2shell, and for context on why a core bug is unusual, read core vs plugin vulnerabilities. If you run login or SSO plugins, a separate critical WordPress flaw landed the same week that updating core does nothing for, and the Forminator RCE is another plugin worth checking.

Found this useful? Share it

Share
Kernel

Software & Business Software Editor

Kernel

I'm US-based, I've daily-driven more Linux distros than I can name, and I treat software like a workshop: what does it do, what does it really cost, and what can I run myself instead. That's why I also cover the CRM, HR and ERP bills that land on a startup the day it signs its first big customer.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading